Blog

Ransomware Gangs Exploit Kickidler in New Attacks

By Mersad • June 11, 2025

Security researchers report a new threat facing businesses that could put your data, as well as its backups, at serious risk. They’ve discovered that ransomware gangs exploit Kickidler in new attacks, meaning that they’re weaponizing your company’s tool to keep things on track against you.


Awareness is the first step in protecting your company from these attacks. Read on to learn more about how cybercriminals use Kickidler’s features against its users.


How Are Hackers Abusing Kickidler?

Companies use Kickidler, an employee monitoring tool, to boost productivity, track employee time, and stay ahead of insider threats. Tools like real-time screen monitoring and keystroke logging help business owners monitor workflow and compliance.


However, cybercriminals are using these features against their victims. They’ve found a way to flip the script, and instead of helping businesses, ransomware gangs exploit Kickidler in new attacks. They are spying on employees, stealing login information, and spreading malware across company networks.


One of the most concerning elements of these attacks is the Smokedham backdoor, a type of malware that gives hackers secret access to infected systems. Once inside, attackers can log every keystroke employee type, watch what they’re doing in real time, and even engage in admin credential theft. In some cases, they’ve also gone after cloud backup credentials, meaning even your data backups aren’t safe if you’re compromised.


Why Antivirus Software Isn’t Detecting the Problem

These attacks are particularly concerning because criminals aren’t using fake versions of Kickidler. Instead, they’re deploying legitimate software in unauthorized ways. By sneaking it onto business computers, they can turn Kickidler into a spying tool that works against the business.



Since the software is legitimate and doesn’t look like malware, traditional antivirus tools often miss it.


What To Do Now To Protect Your Company From an Attack

If you’re using Kickidler (or any other employee monitoring tool), it’s time to look hard at your cybersecurity strategy to identify vulnerabilities and protect your business.


More specifically:


Audit All Software Installations

Make sure you know exactly what employees are installing on your network; even better, limit software installation privileges to trusted IT staff only. Any unapproved installations of Kickidler or other monitoring tools should raise a red flag.


Watch for Unusual Behavior

Unexplained screen activity or strange logins might indicate screen monitoring or keystroke logging. Create alerts for suspicious activity and investigate reports immediately.


Use Endpoint Detection Tools

Standard antivirus software might not catch misuse of legitimate tools like Kickidler. Advanced endpoint detection software can help spot anomalies.


Secure Admin and Cloud Credentials

Don’t store admin credentials or cloud backup credentials in plain text. Use encrypted password managers, enable multi-factor authentication (MFA), and regularly rotate passwords.


Train Your Team

Employees are your first line of defense. Teach them to spot phishing emails, unexpected software behavior, and other red flags.


Don’t Let Criminals Hijack Your System

The fact that ransomware gangs exploit Kickidler in new attacks should serve as a wake-up call for all business owners. The tools designed to protect your company could become the doorway to disaster if not properly managed, so keep your systems tight, your employees informed, and your data locked down. 


Used with permission from Article Aggregator

Related Posts

By BayPointe Technology • September 23, 2026
Help employees recognize phishing emails, verify unusual requests, and report concerns with a practical process for Northeast Ohio businesses.
Stressed man at desk with hand on face, holding glasses near a computer and moving boxes
By BayPointe Technology • September 16, 2026
Recurring IT issues, growing support demands, or unclear security responsibilities? Learn when your Northeast Ohio business should consider managed IT services.
Blue illuminated curved metal structure with repeating ribbed arches
By BayPointe Technology • September 9, 2026
Plan office-move IT tasks, including internet installation, cabling, phones, equipment, vendor coordination, and opening-day readiness checks.
Two coworkers reviewing data on dual monitors in a bright office, one pointing at the screen
By BayPointe Technology • September 2, 2026
Organize business file sharing with clear owners, appropriate permissions, external access reviews, and practical rules employees can follow.
By BayPointe Technology • August 26, 2026
Learn how to define co-managed IT responsibilities, support handoffs, change approvals, and coverage that helps your internal IT team.

Contact Information

1035 Medina Rd, Suite #800

Medina, OH 44256